-
Notifications
You must be signed in to change notification settings - Fork 1.4k
Closed
Labels
Description
- Your Rocket.Chat Experimental app version: 4.7.0.17188
- Your Rocket.Chat server version: 3.3.0
- Deviceyou're running with: Pocophone F1 with Android 10
Steps to reproduce:
- Go to Admin/Permissions and remove the
create-c,create-d,create-p,view-candview-dpermissions for a role such aslivechat-agent - Edit a user by giving it only the
livechat-agentrole - Now if you login as this livechat-agent user:
- In the web application, the icon for creating groups/channels/direct messages doesn't appear, and it can only see private rooms he belongs to (and livechats).
- In the mobile applications (either in Rocket.Chat or Rocket.Chat Experimental), the permissions are not being applied and the user can still create rooms/channels/direct messages and talk to other users.
One question that comes to mind is, are the permissions not being controlled on the server side, just on the client side?
Reactions are currently unavailable